Email / DNS

DMARC Record Generator

Create a DMARC record: choose a policy (none, quarantine, or reject), the share of mail it applies to, report addresses, and alignment, with each option explained.

DMARC Record Generator: DMARC tells receiving mail servers what to do with messages that claim to come from your domain but fail SPF and DKIM checks aligned with the From address, as RFC 7489 defines, and where to send daily reports. The generator writes only the tags you change from their defaults, so the record stays short, and warns when a setting has no effect. Runs 100% locally in your browser with zero server file uploads.

Category
Web tools
Runs
In your browser
Cost
Free · no sign-up
Availability
Ready to use
DMARC record generatorLocal processing

Runs entirely in your browser

DMARCHost / name: _dmarc.example.comType: TXT
v=DMARC1; p=none

With p=none and no report address, the record has no effect: add an rua address to receive reports.

Start with p=none and a report address, read the reports for a few weeks to find every service that sends as your domain, then move to quarantine and reject. DMARC needs SPF or DKIM to pass for the domain in the From address.

Reading the reports

Aggregate reports are XML files, one a day from each large mailbox provider, listing the IP addresses that sent mail as your domain and whether SPF and DKIM passed. Use a mailbox set aside for them, or a reporting service, since busy domains receive many.

If a legitimate service fails, add it to your SPF record with the SPF record generator or set up DKIM signing for it.

Moving to reject

Raise the policy in steps: quarantine with pct=10, then 50, then 100, then reject, watching the reports at each step for legitimate mail that fails.

How to use it

  1. Choose the policy; start with none to collect reports.
  2. Add an address for aggregate reports (rua).
  3. Copy the record into a TXT record named _dmarc on your domain.

Privacy & limitations

The record is built in your browser.

Related tools

Frequently asked questions

Why start with p=none?

It changes nothing for delivery but sends reports showing every service sending as your domain, so you can fix SPF and DKIM before moving to quarantine or reject.

What is alignment?

The domain that passed SPF or DKIM must match the From address. Relaxed alignment accepts the same organisational domain, such as mail.example.com for example.com; strict needs an exact match.

Do I need DMARC?

Gmail and Yahoo require it for bulk senders since 2024, and it stops others from spoofing your domain once you move past p=none.

Free tool · runs in your browser · no account required